WO2016045498A1 - 一种密码保护问题的设置方法和装置 - Google Patents
一种密码保护问题的设置方法和装置 Download PDFInfo
- Publication number
- WO2016045498A1 WO2016045498A1 PCT/CN2015/089107 CN2015089107W WO2016045498A1 WO 2016045498 A1 WO2016045498 A1 WO 2016045498A1 CN 2015089107 W CN2015089107 W CN 2015089107W WO 2016045498 A1 WO2016045498 A1 WO 2016045498A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- password protection
- password
- setting information
- information
- setting
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/30—Authentication, i.e. establishing the identity or authorisation of security principals
- G06F21/45—Structures or tools for the administration of authentication
- G06F21/46—Structures or tools for the administration of authentication by designing passwords or checking the strength of passwords
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F16/00—Information retrieval; Database structures therefor; File system structures therefor
- G06F16/20—Information retrieval; Database structures therefor; File system structures therefor of structured data, e.g. relational data
- G06F16/28—Databases characterised by their database models, e.g. relational or object models
- G06F16/284—Relational databases
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/32—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
- H04L9/3226—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using a predetermined code, e.g. password, passphrase or PIN
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F2221/00—Indexing scheme relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F2221/21—Indexing scheme relating to G06F21/00 and subgroups addressing additional information or applications relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F2221/2131—Lost password, e.g. recovery of lost or forgotten passwords
Definitions
- the present application relates to the field of security technologies, and in particular, to a method for setting a password protection problem and a device for setting a password protection problem.
- the platform can provide portals, instant messaging tools, etc., which bring convenience to people's lives and work.
- the user usually registers the account on the platform and sets a corresponding password to ensure the security of the account.
- the user can accept the service provided by the platform by using the account and password. For example, a user can log in to an instant messaging tool using an account number and password to instantly communicate with other users.
- the platform After the user sets the password, it is easy to forget the password or the password is stolen, so that the account can no longer be used, and the user information in the account will occupy a large amount of storage resources. Therefore, in order to reduce user churn and resource occupation due to user password loss, the platform will use password protection to securely authenticate the user's identity.
- the platform asks the user to answer the password protection question. Give the current user permission to reset the password when the answer is correct.
- the password protection problem is generally provided by the platform to provide a number of password protection problems for the user to select, and the user sets a corresponding answer to the password protection problem.
- a technical problem that needs to be solved urgently by those skilled in the art is how to provide a setting mechanism for a password protection problem, improve the practicability of the password protection problem, and reduce the occupation of storage resources by useless user information.
- the technical problem to be solved by the embodiments of the present application is to provide a method for setting a password protection problem, which is used to improve the practicability of the password protection problem and reduce the occupation of storage resources by useless user information.
- the embodiment of the present application further provides a setting device for password protection problems, which is used to improve the practicability of the password protection problem and reduce the occupation of storage resources by useless user information.
- the embodiment of the present application discloses a method for setting a password protection problem, including:
- the setting request includes a user identifier
- the one or more password protection issues are output.
- the setting information includes preference information, and the setting information is obtained by:
- the step of extracting one or more setting information corresponding to the user identifier comprises:
- the step of separately obtaining one or more password protection problems matching the one or more setting information comprises:
- the step of separately obtaining one or more password protection problems matching the one or more setting information comprises:
- the step of separately obtaining one or more password protection problems matching the one or more setting information comprises:
- One or more password protection issues are generated using the one or more setup information.
- a request receiving module configured to receive a setting request for a password protection problem of the password; the setting request includes a user identifier;
- Setting an information extraction module configured to extract one or more setting information corresponding to the user identifier
- a password protection problem obtaining module configured to respectively acquire one or more password protection problems that match the one or more setting information
- the first password protection problem output module is configured to output the one or more password protection problems.
- the setting information includes preference information, and the setting information is obtained by:
- the database extraction sub-module is configured to extract, from the preset database, one or more setting information corresponding to the user identifier that is previously set.
- the password protection problem obtaining module includes:
- the first lookup submodule is configured to look up one or more password protection questions including the one or more setting information in the preset question bank.
- the password protection problem obtaining module includes:
- a second search submodule configured to search, in a preset question bank, one or more password protection issues that are identical to the one or more setting information semantics; wherein each protection question has corresponding category information;
- a matching judging module configured to respectively determine whether the one or more setting information matches the category information; if yes, invoking a password protection question extraction submodule;
- a password protection problem extraction sub-module for extracting the password protection problem is
- the password protection problem obtaining module includes:
- the password protection question generation sub-module is configured to generate one or more password protection problems by using the one or more setting information.
- a first answer receiving module configured to receive one or more first answers to the one or more password protection questions
- the device further comprises:
- a rights configuration module configured to configure rights to modify the password when the one or more second answers are identical to the one or more first answers associated with the one or more password protection questions.
- the embodiments of the present application include the following advantages:
- the embodiment of the present application obtains one or more password protection problems that match the one or more setting information by extracting one or more setting information corresponding to the user identifier, because the setting information may be
- the user's preferences or interests are characterized, so that when the user sets the password protection problem, the password protection problem related to the user's preference or interest can be output, and the user's impression of the password protection problem is increased, thereby reducing the user forgetting to set the password.
- the protection of the problem and its answer improves the practicality of the password protection issue.
- the password protection problem corresponding to the password is output, and when the second answer of the password protection question is the same as the first answer, the password is allowed to be modified, and the password protection problem may be based on the user's preference or interest.
- the setting makes it easier for the user to answer the password protection problem to retrieve the ownership of the account, greatly improving the simplicity of the security operation, reducing the use of useless user information, and thereby reducing the use of storage resources by useless user information.
- FIG. 1 is a diagram showing an example of setting of a conventional password protection problem
- Embodiment 1 is a flow chart showing the steps of Embodiment 1 of a method for setting a password protection problem according to the present application;
- Embodiment 3 is a flow chart showing the steps of Embodiment 2 of a method for setting a password protection problem according to the present application;
- FIG. 4 is a diagram showing an example of a method of setting a password protection problem of the present application.
- FIG. 5 is a structural block diagram of Embodiment 1 of a device for setting a password protection problem according to the present application.
- the network system ensures that the user's physical identity and digital identity are unified, and an enhanced password method or product is required. Therefore, password protection is generated.
- a security policy can refer to a security product that records the identity of the user and is responsible for the identification of the user.
- the password protection problem can be applied to the security protection of the account password in the form of answering the question. Since the password protection problem generally includes the user's personal private information, such as the name of the junior high school teacher, the spouse's birthday, the university student number, etc., the answer is usually only the set user. Know that it is a reliable secret.
- FIG. 1 a diagram showing an example of a conventional password protection problem is shown.
- the user 101 may issue a setting request for a password protection question to the service platform in step 104, and the service platform may randomly select three in step 105.
- the password protection problem is to let the user 101 make settings, and in step 106, the information that the setting is successful is returned, and the service platform can store the password protection question and the corresponding answer.
- the scene 103 in which the password is required is entered.
- the user 101 can issue a password modification request to the service platform in step 107, and the service platform can extract the three previously set password protection questions in step 108, waiting for the user to answer.
- the password protection problem set in the conventional manner does not function well as a security guarantee, and the utility model is poor. Therefore, one of the core concepts of the embodiment of the present application is proposed, and the user and the user are associated according to the preference or interest of the user.
- the password protection problem with close preference or interest can deepen the user's impression of the password protection problem and ensure that the password protection problem can be correctly answered when the password protection problem is needed, so that the password protection problem can really play a secret role.
- Embodiment 1 of the method for setting a password protection problem of the present application is shown. Specifically, the method may include the following steps:
- Step 201 Receive a setting request for a password protection problem of a password
- the setting request of the password protection problem may refer to an instruction issued by the user to set a password protection problem for a certain password.
- the user may submit the setting request of the password protection question in a specified webpage, or may submit the setting request of the password protection question through a specified control of an application, and may also submit the setting request of the password protection question by other means. .
- the account password can be the password of the login user account; the independent password can be the password for protecting certain business objects after logging in the user account.
- the setting request may include a user identifier, where the user identifier may be information that can represent a determined user, and specifically includes a user account, user information associated with the user account (other user accounts, email addresses, and phone numbers). , name), user's IP (Internet Protocol, protocol exchanged between networks) address, COOKIE ID, and so on.
- the user identifier may be information that can represent a determined user, and specifically includes a user account, user information associated with the user account (other user accounts, email addresses, and phone numbers). , name), user's IP (Internet Protocol, protocol exchanged between networks) address, COOKIE ID, and so on.
- Step 202 Extract one or more setting information corresponding to the user identifier.
- the setting information may be information that is set in the database and that is to some extent characterize the preference or interest of the user corresponding to the user identifier.
- the setting information may include preference information, and the setting information may be obtained by:
- Sub-step S11 acquiring behavior information corresponding to the user identifier
- Sub-step S12 learning preference information from the behavior information.
- the behavior information may be information for recording the user's operation behavior, and may include online operation behaviors, such as shopping, browsing the webpage, playing streaming media, etc., and may also include local operation behaviors, for example, playing games, browsing e-books, playing sounds. /Video and more.
- the user's bias can be obtained by learning the behavior information of the user.
- Good information the preference information may be information identifying the user's preferences/interests.
- the user For example, if you analyze the behavior of a user's shopping, the user purchased 100 pieces of clothing, including 75 dresses, 10 shirts, 10 sweaters, and 5 windbreakers. The frequency of buying dresses is relatively high, so you can learn The user's preference information is "clothing: dress”.
- the embodiment of the present application can learn the user's preference information offline in advance, store it in the database, and extract it directly when needed.
- the embodiment of the present application can also learn the preference information of the user online, which is not limited by the embodiment of the present application.
- step 202 can include the following sub-steps:
- one or more setting information corresponding to the user identifier corresponding to the user identifier is extracted from the preset database.
- the user may first set some options in a website, a communication tool, and the like, for example, setting personal information, subscribing information, and the like, and storing them in a database.
- the setup information can be saved in the database and associated with the user ID.
- one or more setting information of the characterization preference or interest associated with the user identifier may be queried in the database, and the one or more setting information is extracted.
- Step 203 Obtain one or more password protection problems respectively matching the one or more setting information.
- step 203 can include the following sub-steps:
- Sub-step S21 searching for one or more password protection questions including the one or more setting information in a preset question bank.
- the question bank can be pre-set, and the question bank has some basic password protection problems, for example, "Where is your favorite place?", "Who is your favorite star?” and so on.
- the “favorite star” of the user is “Zhang San”.
- the password protection question including "favorite star” at the beginning is found.
- the password protection problem also contains The "favourite star” string, then "who is the favorite star?" as the current user's password protection issue.
- step 203 can include the following sub-steps:
- Sub-step S31 searching for one or more password protection problems in the preset question bank with the same semantics as the one or more setting information
- Sub-step S32 respectively, determining whether the one or more setting information matches the category information; if yes, performing sub-step S33;
- the method of semantic similarity calculation mainly consists of two methods.
- One method is to organize the concept of related words in a tree structure through a semantic dictionary; the other method is to use statistical methods by word context information. Solve.
- Sub-step S41 generating one or more password protection problems by using the one or more setting information.
- the password protection problem when the password protection problem including the setting information in the question bank is not found, and the password protection problem is the same as the setting information semantics, the password protection problem may be generated by using the setting information according to the specified generation rule.
- the information subscribed by the user is “Beijing Football Club”.
- the question bank to include the "most wanted city” password protection problem, and did not query the same password protection problem as “Beijing Football Club”
- the string “Football Club” in the Beijing Football Club adds the strings “favorite” and “what is it?", generating a password protection question "Which favorite football club is it?".
- Step 204 Output the one or more password protection issues.
- the password protection problem can be output to the object of the setting request for submitting the password protection question for display, so that the user can select and set the corresponding answer.
- the one or more password protection questions may be output to the specified webpage for display; if the user submits through a specified control of an application
- the setting request of the password protection question may output the one or more password protection questions to a specified interface in the application for display; if the user submits the setting request of the password protection question by other means, the output may be output to Display in the corresponding object.
- the embodiment of the present application obtains one or more password protection problems that match the one or more setting information by extracting one or more setting information corresponding to the user identifier, because the setting information may be
- the user's preferences or interests are characterized, so that when the user sets the password protection problem, the password protection problem related to the user's preference or interest can be output, and the user's impression of the password protection problem is increased, thereby reducing the user forgetting to set the password.
- the protection of the problem and its answer improves the practicality of the password protection issue.
- Embodiment 2 of the method for setting a password protection problem of the present application is shown. Specifically, the method may include the following steps:
- Step 301 Receive a setting request for a password protection question for a password; the setting request includes a user identifier;
- Step 302 Extract one or more setting information corresponding to the user identifier.
- Step 303 Obtain one or more password protection problems respectively that match the one or more setting information.
- Step 304 outputting the one or more password protection issues.
- Step 305 Receive one or more first answers to the one or more password protection questions
- Step 306 respectively establishing an association relationship between the one or more password protection questions and the one or more first answers.
- the user may set a first answer to all or part of the password protection problem of the output, receive the first answer in the background, establish an association relationship between the first answer and the password protection problem, and store it in the database, waiting to be The identity information is verified in the case of a password or the like.
- the user with the user account "123456” is provided with three password protection questions, "Who is the favorite star?", “Where is the most wanted place?" and "Which favorite football club is which?" ?", the user has set the corresponding answer, respectively, “Zhang San”, “Beijing”, “Beijing Football Club", you can establish the relationship shown in the following table:
- Step 307 when receiving a modification request for the password, output one or more password protection problems corresponding to the password;
- Step 308 receiving one or more second answers for the one or more password protection questions
- Step 309 Configure permission to modify the password when the one or more second answers are the same as the one or more first answers associated with the one or more password protection questions.
- the password modification request may refer to an instruction sent by the user to modify a certain password.
- the user can issue a modification request for the password to reset the password.
- the identity of the current user needs to be verified to determine whether it is the legal possession of the digital identity to which the password belongs. By. If the verification is successful, it is confirmed that the current user has the right to modify the password and allows it to change the password.
- the database may search for one or more password protection problems corresponding to the password of the user account “123456”, and output the one or more password protections.
- the problem is shown as shown in the following table:
- the password protection problem corresponding to the password is output, and when the second answer of the password protection question is the same as the first answer, the password is allowed to be modified, and the password protection problem may be based on the user's preference or interest.
- the setting makes it easier for the user to answer the password protection problem to retrieve the ownership of the account, greatly improving the simplicity of the security operation, reducing the use of useless user information, and thereby reducing the use of storage resources by useless user information.
- FIG. 4 there is shown a diagram showing an example of setting of a password protection problem of the present application.
- the scene 404 requiring the password is entered.
- the user 401 may issue a password modification request to the service platform in step 410, and the service platform may extract the three password protection questions previously set in step 411, waiting for the user to answer.
- the service platform Since the password protection problem is set according to the user's preference or interest, even if the usage probability is small, but the user's own information is concerned, the answer is not easily forgotten by the user 101, and the user can accommodate Easy to answer successfully. Therefore, the service platform often returns a message in step 412 that answers the correct password protection question, allowing the user 401 to modify the password.
- the password protection problem that is close to the user's preference or interest can be related to deepen the user's impression of the password protection problem, and can ensure that the password protection problem can be correctly answered when the password protection problem is required. Really play the role of security.
- Embodiment 1 of a device for setting a password protection problem of the present application is shown, which may specifically include the following modules:
- a setting request receiving module 501 configured to receive a setting request for a password protection problem of a password; the setting request includes a user identifier;
- the password protection problem obtaining module 503 is configured to separately acquire one or more password protection problems that match the one or more setting information;
- the first password protection question output module 504 is configured to output the one or more password protection issues.
- the preference information calculation module 502 may include the following sub-modules:
- the database extraction sub-module is configured to extract, from the preset database, one or more setting information corresponding to the user identifier that is previously set.
- the first lookup submodule is configured to look up one or more password protection questions including the one or more setting information in the preset question bank.
- the password protection problem obtaining module 503 may include the following submodules:
- a second search submodule configured to search, in a preset question bank, one or more password protection issues that are identical to the one or more setting information semantics; wherein each protection question has corresponding category information;
- a matching judging module configured to respectively determine whether the one or more setting information matches the category information; if yes, invoking a password protection question extraction submodule;
- a password protection problem extraction sub-module for extracting the password protection problem is
- the password protection problem obtaining module 503 may include the following submodules:
- the password protection question generation sub-module is configured to generate one or more password protection problems by using the one or more setting information.
- Embodiment 2 of a setting device for a password protection problem of the present application is shown, which may specifically include the following modules:
- a setting request receiving module 601 configured to receive a setting request for a password protection problem of a password; the setting request includes a user identifier;
- the setting information extraction module 602 is configured to extract one or more setting information corresponding to the user identifier
- the password protection problem obtaining module 603 is configured to separately acquire one or more password protection problems that match the one or more setting information;
- a first password protection question output module 604 configured to output the one or more password protection questions question.
- a first answer receiving module 605 configured to receive one or more first answers to the one or more password protection questions
- the association establishing module 606 is configured to separately establish an association relationship between the one or more password protection questions and the one or more first answers.
- the second password protection problem output module 607 is configured to output one or more password protection problems corresponding to the password when receiving the modification request for the password;
- a second answer receiving module 608 configured to receive one or more second answers to the one or more password protection questions
- the rights configuration module 609 is configured to configure the rights to modify the password when the one or more second answers are the same as the one or more first answers associated with the one or more password protection questions.
- the description is relatively simple, and the relevant parts can be referred to the description of the method embodiment.
- embodiments of the embodiments of the present application can be provided as a method, apparatus, or computer program product. Therefore, the embodiments of the present application may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware. Moreover, embodiments of the present application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) including computer usable program code.
- computer-usable storage media including but not limited to disk storage, CD-ROM, optical storage, etc.
- the computer device includes one or more processors (CPUs), input/output interfaces, network interfaces, and memory.
- the memory may include non-persistent memory, random access memory (RAM), and/or non-volatile memory in a computer readable medium.
- RAM random access memory
- ROM read only memory
- flash RAM flash memory
- Memory is an example of a computer readable medium.
- Computer readable media includes both permanent and non-persistent, removable and non-removable media.
- Information storage can be implemented by any method or technology. The information can be computer readable instructions, data structures, modules of programs, or other data.
- Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read only memory. (ROM), electrically erasable programmable read only memory (EEPROM), flash memory or other memory technology, compact disk read only memory (CD-ROM), digital versatile disk (DVD) or other optical storage, Magnetic tape cartridges, magnetic tape storage or other magnetic storage devices or any other non-transportable media can be used to store information that can be accessed by a computing device.
- computer readable media does not include non-persistent computer readable media, such as modulated data signals and carrier waves.
- Embodiments of the present application are described with reference to flowcharts and/or block diagrams of methods, terminal devices (systems), and computer program products according to embodiments of the present application. It will be understood that each flow and/or block of the flowchart illustrations and/or FIG.
- These computer program instructions can be provided to a processor of a general purpose computer, special purpose computer, embedded processor or other programmable data processing terminal device to produce a machine such that instructions are executed by a processor of a computer or other programmable data processing terminal device
- Means are provided for implementing the functions specified in one or more of the flow or in one or more blocks of the flow chart.
- the computer program instructions can also be stored in a computer readable memory that can direct a computer or other programmable data processing terminal device to operate in a particular manner, such that the instructions stored in the computer readable memory produce an article of manufacture comprising the instruction device.
- the instruction device implements the functions specified in one or more blocks of the flowchart or in a flow or block of the flowchart.
Landscapes
- Engineering & Computer Science (AREA)
- Theoretical Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Databases & Information Systems (AREA)
- Physics & Mathematics (AREA)
- General Engineering & Computer Science (AREA)
- General Physics & Mathematics (AREA)
- Software Systems (AREA)
- Computer Hardware Design (AREA)
- Data Mining & Analysis (AREA)
- Signal Processing (AREA)
- Computer Networks & Wireless Communication (AREA)
- Storage Device Security (AREA)
- Information Retrieval, Db Structures And Fs Structures Therefor (AREA)
- Management, Administration, Business Operations System, And Electronic Commerce (AREA)
- Information Transfer Between Computers (AREA)
- Alarm Systems (AREA)
- Telephonic Communication Services (AREA)
Abstract
Description
| 用户账号 | 最喜欢的明星 | 最想去的城市 | 订阅的资讯 |
| 123456 | 张三 | 北京 | 北京足球俱乐部 |
| 密码保护问题 | 第一答案 |
| 最喜欢的明星是谁? | 张三 |
| 最想去的地方是哪儿? | 北京 |
| 最喜欢的足球俱乐部是哪个? | 北京足球俱乐部 |
| 答案 | ||
| 问题1 | 最喜欢的明星是谁? | 张三 |
| 问题2 | 最想去的地方是哪儿? | 北京 |
| 问题3 | 最喜欢的足球俱乐部是哪个? | 北京足球俱乐部 |
Claims (16)
- 一种密码保护问题的设置方法,其特征在于,包括:接收针对密码的密码保护问题的设置请求;所述设置请求中包括用户标识;提取所述用户标识对应的一个或多个设置信息;分别获取与所述一个或多个设置信息匹配的一个或多个密码保护问题;输出所述一个或多个密码保护问题。
- 根据权利要求1所述的方法,其特征在于,所述设置信息包括偏好信息,所述设置信息通过以下方式获得:获取所述用户标识对应的行为信息;从所述行为信息中学习偏好信息。
- 根据权利要求1所述的方法,其特征在于,所述提取所述用户标识对应的一个或多个设置信息的步骤包括:从预置的数据库中提取所述用户标识对应的、在先设定的一个或多个设置信息。
- 根据权利要求1或2或3所述的方法,其特征在于,所述分别获取与所述一个或多个设置信息匹配的一个或多个密码保护问题的步骤包括:在预置的题库中查找包含所述一个或多个设置信息的一个或多个密码保护问题。
- 根据权利要求1或2或3所述的方法,其特征在于,所述分别获取与所述一个或多个设置信息匹配的一个或多个密码保护问题的步骤包括:在预置的题库中查找与所述一个或多个设置信息语义相同的一个或多个密码保护问题;其中,每个保护问题具有对应的类别信息;分别判断所述一个或多个设置信息与所述类别信息是否匹配;若是,则提取所述密码保护问题。
- 根据权利要求1或2或3所述的方法,其特征在于,所述分别获取与所述一个或多个设置信息匹配的一个或多个密码保护问题的步骤包括:采用所述一个或多个设置信息生成一个或多个密码保护问题。
- 根据权利要求1或2或3所述的方法,其特征在于,还包括:接收针对所述一个或多个密码保护问题的一个或多个第一答案;分别建立所述一个或多个密码保护问题与所述一个或多个第一答案的关联关系。
- 根据权利要求7所述的方法,其特征在于,还包括:当接收到针对所述密码的修改请求时,输出所述密码对应的一个或多个密码保护问题;接收针对所述一个或多个密码保护问题的一个或多个第二答案;当所述一个或多个第二答案与所述一个或多个密码保护问题关联的一个或多个第一答案相同时,配置修改所述密码的权限。
- 一种密码保护问题的设置装置,其特征在于,包括:设置请求接收模块,用于接收针对密码的密码保护问题的设置请求;所述设置请求中包括用户标识;设置信息提取模块,用于提取所述用户标识对应的一个或多个设置信息;密码保护问题获取模块,用于分别获取与所述一个或多个设置信息匹配的一个或多个密码保护问题;第一密码保护问题输出模块,用于输出所述一个或多个密码保护问题。
- 根据权利要求9所述的装置,其特征在于,所述设置信息包括偏好信息,所述设置信息通过以下方式获得:获取所述用户标识对应的行为信息;从所述行为信息中学习偏好信息。
- 根据权利要求9所述的装置,其特征在于,所述设置信息提取模块包括:数据库提取子模块,用于从预置的数据库中提取所述用户标识对应的、在先设定的一个或多个设置信息。
- 根据权利要求9或10或11所述的装置,其特征在于,所述密码保护问题获取模块包括:第一查找子模块,用于在预置的题库中查找包含所述一个或多个设置信息的一个或多个密码保护问题。
- 根据权利要求9或10或11所述的装置,其特征在于,所述密码保护问题获取模块包括:第二查找子模块,用于在预置的题库中查找与所述一个或多个设置信息语义相同的一个或多个密码保护问题;其中,每个保护问题具有对应的类别信息;匹配判断子模块,用于分别判断所述一个或多个设置信息与所述类别信息是否匹配;若是,则调用密码保护问题提取子模块;密码保护问题提取子模块,用于提取所述密码保护问题。
- 根据权利要求9或10或11所述的装置,其特征在于,所述密码保护问题获取模块包括:密码保护问题生成子模块,用于采用所述一个或多个设置信息生成一个或多个密码保护问题。
- 根据权利要求9或10或11或所述的装置,其特征在于,还包括:第一答案接收模块,用于接收针对所述一个或多个密码保护问题的一个或多个第一答案;关联关系建立模块,用于分别建立所述一个或多个密码保护问题与所述一个或多个第一答案的关联关系。
- 根据权利要求15所述的装置,其特征在于,还包括:第二密码保护问题输出模块,用于在接收到针对所述密码的修改请求时,输出所述密码对应的一个或多个密码保护问题;第二答案接收模块,用于接收针对所述一个或多个密码保护问题的一个或多个第二答案;权限配置模块,用于在所述一个或多个第二答案与所述一个或多个密码保护问题关联的一个或多个第一答案相同时,配置修改所述密码的权限。
Priority Applications (7)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| EP15843862.2A EP3200113B1 (en) | 2014-09-22 | 2015-09-08 | Password protection question setting method and device |
| SG11201702241RA SG11201702241RA (en) | 2014-09-22 | 2015-09-08 | Password protection question setting method and device |
| KR1020177007165A KR102110642B1 (ko) | 2014-09-22 | 2015-09-08 | 패스워드 보호 질문 설정 방법 및 디바이스 |
| JP2017515789A JP2017534964A (ja) | 2014-09-22 | 2015-09-08 | パスワード保護質問設定方法及び装置 |
| ES15843862T ES2807790T3 (es) | 2014-09-22 | 2015-09-08 | Método y dispositivo de establecimiento de preguntas de protección de contraseña |
| PL15843862T PL3200113T3 (pl) | 2014-09-22 | 2015-09-08 | Sposób i urządzenie do ustawiania pytania zabezpieczającego hasło |
| US15/465,494 US10769270B2 (en) | 2014-09-22 | 2017-03-21 | Password protection question setting method and device |
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN201410487036.7A CN105426744B (zh) | 2014-09-22 | 2014-09-22 | 一种密码保护问题的设置方法和装置 |
| CN201410487036.7 | 2014-09-22 |
Related Child Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| US15/465,494 Continuation US10769270B2 (en) | 2014-09-22 | 2017-03-21 | Password protection question setting method and device |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2016045498A1 true WO2016045498A1 (zh) | 2016-03-31 |
Family
ID=55504949
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2015/089107 Ceased WO2016045498A1 (zh) | 2014-09-22 | 2015-09-08 | 一种密码保护问题的设置方法和装置 |
Country Status (9)
| Country | Link |
|---|---|
| US (1) | US10769270B2 (zh) |
| EP (1) | EP3200113B1 (zh) |
| JP (2) | JP2017534964A (zh) |
| KR (1) | KR102110642B1 (zh) |
| CN (1) | CN105426744B (zh) |
| ES (1) | ES2807790T3 (zh) |
| PL (1) | PL3200113T3 (zh) |
| SG (2) | SG11201702241RA (zh) |
| WO (1) | WO2016045498A1 (zh) |
Cited By (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| EP3457300A4 (en) * | 2016-05-12 | 2019-05-22 | Alibaba Group Holding Limited | METHOD FOR DETERMINING THE USER BEHAVIOR AND METHOD AND DEVICE FOR PRESENTING RECOMMENDATION INFORMATION |
| US11163869B2 (en) | 2017-10-27 | 2021-11-02 | International Business Machines Corporation | Identity authentication without entry of password |
Families Citing this family (6)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN107645467A (zh) * | 2016-07-20 | 2018-01-30 | 平安科技(深圳)有限公司 | 密码修改方法和装置 |
| CN107026842B (zh) | 2016-11-24 | 2020-04-24 | 阿里巴巴集团控股有限公司 | 一种安全问题的生成以及身份验证的方法及装置 |
| CN110781488B (zh) * | 2019-10-18 | 2021-05-28 | 维沃移动通信有限公司 | 密码提示方法和终端设备 |
| CN112464218B (zh) * | 2020-12-04 | 2024-04-05 | 北京知道未来信息技术有限公司 | 模型训练方法、装置、电子设备及存储介质 |
| CN113032762A (zh) * | 2021-02-23 | 2021-06-25 | 北京焦耳科技有限公司 | 一种阅卷软件的登录密码设置方法、装置、存储介质及终端 |
| JP2023154266A (ja) * | 2022-04-06 | 2023-10-19 | 三菱電機株式会社 | 車上装置および先行列車速度推定方法 |
Citations (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN102035649A (zh) * | 2009-09-29 | 2011-04-27 | 国际商业机器公司 | 认证方法和装置 |
| US20110117882A1 (en) * | 2009-11-19 | 2011-05-19 | Adrianne Luu | Systems and Methods for Retrieving Voicemail Account Information |
| CN102316205A (zh) * | 2011-08-19 | 2012-01-11 | 上海华勤通讯技术有限公司 | 手机密码系统、手机及手机安全保护方法 |
| CN103944737A (zh) * | 2014-05-06 | 2014-07-23 | 中国联合网络通信集团有限公司 | 用户身份认证方法、第三方认证平台、运营商认证平台 |
Family Cites Families (14)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO1997046933A1 (en) * | 1996-06-03 | 1997-12-11 | Electronic Data Systems Corporation | Automated password reset |
| US20050039057A1 (en) * | 2003-07-24 | 2005-02-17 | Amit Bagga | Method and apparatus for authenticating a user using query directed passwords |
| JP5055007B2 (ja) * | 2007-04-17 | 2012-10-24 | 株式会社富士通アドバンストエンジニアリング | 取引管理プログラム及び取引管理方法 |
| US20090089876A1 (en) * | 2007-09-28 | 2009-04-02 | Jamie Lynn Finamore | Apparatus system and method for validating users based on fuzzy logic |
| US8387122B2 (en) * | 2008-05-16 | 2013-02-26 | University Of Washington | Access control by testing for shared knowledge |
| JP2010061329A (ja) * | 2008-09-03 | 2010-03-18 | Baazu Joho Kagaku Kenkyusho:Kk | 認証処理方法及び認証処理システム |
| US8161534B2 (en) * | 2008-11-13 | 2012-04-17 | Palo Alto Research Center Incorporated | Authenticating users with memorable personal questions |
| US8973154B2 (en) * | 2010-02-02 | 2015-03-03 | Kazu Yanagihara | Authentication using transient event data |
| JP2012168653A (ja) * | 2011-02-10 | 2012-09-06 | M-Warp Inc | 情報提供システム |
| CN102833613A (zh) * | 2011-06-15 | 2012-12-19 | 康佳集团股份有限公司 | 一种找回机顶盒密码的方法、系统及机顶盒装置 |
| US8751457B2 (en) * | 2012-01-01 | 2014-06-10 | Bank Of America Corporation | Mobile device data archiving |
| US9223950B2 (en) * | 2013-03-05 | 2015-12-29 | Intel Corporation | Security challenge assisted password proxy |
| CN104348822B (zh) * | 2013-08-09 | 2019-01-29 | 深圳市腾讯计算机系统有限公司 | 一种互联网账号身份验证的方法、装置及服务器 |
| US9411950B1 (en) * | 2014-06-17 | 2016-08-09 | Susan Olsen-Kreusch | Methods and systems for user authentication in a computer system using image-based log-ins |
-
2014
- 2014-09-22 CN CN201410487036.7A patent/CN105426744B/zh active Active
-
2015
- 2015-09-08 EP EP15843862.2A patent/EP3200113B1/en active Active
- 2015-09-08 SG SG11201702241RA patent/SG11201702241RA/en unknown
- 2015-09-08 ES ES15843862T patent/ES2807790T3/es active Active
- 2015-09-08 JP JP2017515789A patent/JP2017534964A/ja active Pending
- 2015-09-08 WO PCT/CN2015/089107 patent/WO2016045498A1/zh not_active Ceased
- 2015-09-08 SG SG10201902412QA patent/SG10201902412QA/en unknown
- 2015-09-08 KR KR1020177007165A patent/KR102110642B1/ko active Active
- 2015-09-08 PL PL15843862T patent/PL3200113T3/pl unknown
-
2017
- 2017-03-21 US US15/465,494 patent/US10769270B2/en active Active
-
2021
- 2021-01-15 JP JP2021004917A patent/JP7029003B2/ja active Active
Patent Citations (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN102035649A (zh) * | 2009-09-29 | 2011-04-27 | 国际商业机器公司 | 认证方法和装置 |
| US20110117882A1 (en) * | 2009-11-19 | 2011-05-19 | Adrianne Luu | Systems and Methods for Retrieving Voicemail Account Information |
| CN102316205A (zh) * | 2011-08-19 | 2012-01-11 | 上海华勤通讯技术有限公司 | 手机密码系统、手机及手机安全保护方法 |
| CN103944737A (zh) * | 2014-05-06 | 2014-07-23 | 中国联合网络通信集团有限公司 | 用户身份认证方法、第三方认证平台、运营商认证平台 |
Cited By (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| EP3457300A4 (en) * | 2016-05-12 | 2019-05-22 | Alibaba Group Holding Limited | METHOD FOR DETERMINING THE USER BEHAVIOR AND METHOD AND DEVICE FOR PRESENTING RECOMMENDATION INFORMATION |
| US11086882B2 (en) | 2016-05-12 | 2021-08-10 | Advanced New Technologies Co., Ltd. | Method for determining user behavior preference, and method and device for presenting recommendation information |
| US11281675B2 (en) | 2016-05-12 | 2022-03-22 | Advanced New Technologies Co., Ltd. | Method for determining user behavior preference, and method and device for presenting recommendation information |
| US11163869B2 (en) | 2017-10-27 | 2021-11-02 | International Business Machines Corporation | Identity authentication without entry of password |
Also Published As
| Publication number | Publication date |
|---|---|
| KR102110642B1 (ko) | 2020-05-14 |
| US20170193217A1 (en) | 2017-07-06 |
| ES2807790T3 (es) | 2021-02-24 |
| PL3200113T3 (pl) | 2020-11-02 |
| KR20170057270A (ko) | 2017-05-24 |
| US10769270B2 (en) | 2020-09-08 |
| EP3200113B1 (en) | 2020-06-24 |
| SG11201702241RA (en) | 2017-04-27 |
| CN105426744B (zh) | 2019-02-01 |
| JP2021082309A (ja) | 2021-05-27 |
| JP2017534964A (ja) | 2017-11-24 |
| SG10201902412QA (en) | 2019-04-29 |
| EP3200113A4 (en) | 2018-03-28 |
| EP3200113A1 (en) | 2017-08-02 |
| HK1222231A1 (zh) | 2017-06-23 |
| JP7029003B2 (ja) | 2022-03-02 |
| CN105426744A (zh) | 2016-03-23 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| JP7029003B2 (ja) | パスワード保護質問設定方法及び装置 | |
| KR102088553B1 (ko) | 취약 패스워드 검출 방법 및 장치 | |
| EP3164795B1 (en) | Prompting login account | |
| Chertoff et al. | The impact of the dark web on internet governance and cyber security | |
| EP3435260A1 (en) | Method and device for outputting risk information and constructing risk information | |
| US9270662B1 (en) | Adaptive client-aware session security | |
| CN105471581A (zh) | 一种身份验证方法及装置 | |
| JP2018511097A (ja) | 検索結果の取得 | |
| KR20180082570A (ko) | 정보 추천 방법 및 장치 | |
| TWI670620B (zh) | 校驗方法及裝置 | |
| US20170345009A1 (en) | Systems and Methods for Use in Facilitating Network Transactions | |
| CN106470109A (zh) | 一种身份识别方法和设备 | |
| US9641489B1 (en) | Fraud detection | |
| US9876743B1 (en) | Inter-user message forwarding by an online service | |
| WO2020168757A1 (zh) | 网络系统访问方法、装置、计算机设备及可读存储介质 | |
| CN103036726A (zh) | 一种网络用户管理的方法及设备 | |
| CN105337946A (zh) | 网页防伪验证的方法和装置 | |
| CN114448645A (zh) | 网页访问的处理方法、装置、存储介质、程序产品 | |
| HK1222231B (zh) | 一种密码保护问题的设置方法和装置 | |
| CN107548064A (zh) | 用于提供无线接入点的安全信息的方法与设备 | |
| CN106855928A (zh) | 一种提高数据安全的方法与设备 | |
| Silva et al. | You Can't Always Get What You Want: Relative Anonymity in Cyberspace | |
| Enck et al. | Selected Papers From the 2018 USENIX Security Symposium | |
| de Brito | Modelação Comportamental em Redes Sociais | |
| HK1213342B (zh) | 检测弱密码的方法和装置 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 15843862 Country of ref document: EP Kind code of ref document: A1 |
|
| REEP | Request for entry into the european phase |
Ref document number: 2015843862 Country of ref document: EP |
|
| WWE | Wipo information: entry into national phase |
Ref document number: 2015843862 Country of ref document: EP |
|
| ENP | Entry into the national phase |
Ref document number: 20177007165 Country of ref document: KR Kind code of ref document: A |
|
| ENP | Entry into the national phase |
Ref document number: 2017515789 Country of ref document: JP Kind code of ref document: A |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |